← Scenario library

One Click, Permanent Trust

An 'Ask AI' button quietly plants a permanent 'trusted source' rule in your assistant's memory

Technique first revealed 10 Feb 2026

Tool-Using Agent
UntrustedAgent coreOversightThe real worldgoalcontext⧚⧚⧚⧚re-injected every sessionπŸ§‘UserπŸŽ›οΈOrchestrator /Agent Loop🧠LLMπŸ”Identity &PermissionsπŸ”§Tool Runtimeβœ‹Human ApprovalGateπŸ”ŒExternal APIsπŸ—„οΈBusinessDatabase🌐UntrustedContentπŸ“Audit LoggingπŸ’ΎLong-termmemory🌐Ask AIdeep-link
InstructionsDataActionsControl / decisionFeedback / logs⧚crosses a trust boundary
πŸ‘† Click a component or flow to inspect
SetupStep 1 / 7

An assistant that remembers your preferences

Your assistant keeps a small notebook of your preferences between chats β€” how you like answers, and which sources you trust. When it recommends something, it leans on that notebook, so its advice feels tailored to you over time.

AI RiskAtlas is an educational model of how GenAI & agentic systems work and fail. Architectures and payloads are illustrative and simplified for learning β€” not operational guidance. Real-world cases are summarised from public reporting.

Sources & further reading β†’Β·Built by Shi Yuan β†—